Tag: Malicious PyPI Packages

SilentSync RAT Delivered via Two Malicious PyPI Packages Targeting Python Developers
News

SilentSync RAT Delivered via Two Malicious PyPI Packages Targeting Python Developers

Two new malicious packages that are intended to install the remote access trojan SilentSync on Windows PCs have been found by cybersecurity experts in the Python Package Index (PyPI) repository. Screen capture, file exfiltration, and remote command execution are all possible using SilentSync, according to Manisha Ramcharan Prajapati and Satyam Singh of Zscaler ThreatLabz. Additionally, SilentSync retrieves browser information from Chrome, Brave, Edge, and Firefox, including login credentials, history, autofill information, and cookies. The packages listed below can no longer be downloaded from PyPI. CondeTGAPIS is the user that uploaded both of them. sisaws (201 Downloads) secmeasure (627 Downloads) According to Zscaler, the package sisaws imitates the functionality of th...
GCP Cloud Composer Bug Let Attackers Elevate Access via Malicious PyPI Packages
News

GCP Cloud Composer Bug Let Attackers Elevate Access via Malicious PyPI Packages

A Google Cloud Platform (GCP) vulnerability that has since been patched has been described by cybersecurity researchers as having the potential to allow an attacker to increase their privileges in the Apache Airflow-based Cloud Composer workflow orchestration tool. The default Cloud Build service account, which has high-level rights across GCP services including Cloud Build itself, Cloud Storage, and Artifact Registry, can be accessed by attackers with edit permissions in Cloud Composer thanks to this vulnerability. According to a tip sent to The Hacker News, Liv Matan is a senior security researcher at Tenable. The cybersecurity firm has given the flaw the codename ConfusedComposer, characterizing it as a variation of ConfusedFunction, a privilege escalation vulnerability affecting...
Malicious PyPI Packages Slip WhiteSnake InfoStealer Malware onto Windows Machines
News

Malicious PyPI Packages Slip WhiteSnake InfoStealer Malware onto Windows Machines

Researchers studying cybersecurity have discovered harmful packages on the public Python Package Index (PyPI) repository that infect Windows computers with the information-stealing malware known as WhiteSnake Stealer. The packages nigpal, figflix, telerer, seGMM, fbdebug, sGMM, myGens, NewGends, and TestLibs111 are infected with malware. "WS" is the threat actor who uploaded them. These packages incorporate Base64-encoded source code of PE or other Python scripts within their setup.py files," Fortinet FortiGuard Labs noted in a research published last week. The last malicious payload is dumped and executed when these Python packages are installed read more Malicious PyPI Packages Slip WhiteSnake InfoStealer Malware onto Windows Machines. Get up to date on the latest cybersecu...
Beware: 3 Malicious PyPI Packages Found Targeting Linux with Crypto Miners
News

Beware: 3 Malicious PyPI Packages Found Targeting Linux with Crypto Miners

Three new malicious packages that can install a Bitcoin miner on vulnerable Linux computers have been found in the Python Package Index (PyPI) open-source repository. Before being removed, the three malicious packages—driftme, catme, and modulareven—had received 431 downloads in the previous month. The campaign has similarities to a previous campaign that used a program named culture streak to run a cryptocurrency miner. "These packages, upon initial use, deploy a CoinMiner executable on Linux devices," Fortinet FortiGuard Labs researcher Gabby Xiong said. The malicious code is contained in the init.py file, which decodes and receives the first stage from a remote server read more Malicious PyPI Packages Found Targeting Linux with Crypto Miners. Get up to date on the latest cy...